Favicon of supply-chain-security

supply-chain-security Skill

AI Agent SkillSecurityPowerShellOpen source

Software supply chain security reference for OpenSSF Scorecard, SLSA, Sigstore, SBOM, and posture/backlog taxonomies. Published by microsoft in hve-core.

What is supply-chain-security Skill?

Software supply chain security reference for OpenSSF Scorecard, SLSA, Sigstore, SBOM, and posture/backlog taxonomies. Published by microsoft in hve-core. This profile combines repository metadata with install, compatibility, and usage signals so developers can quickly decide whether it fits their agent workflow before opening the source repository.

Trust signal
95/100
Maintenance signal
90/100
Adoption signal
77/100

Automated repository signals based on public metadata such as recency, license, installation evidence, and adoption. These are not a security audit or endorsement.

Key capabilities

  • Includes SKILL.md support
  • Reusable instructions support
  • Security review
  • Security review use cases

Technical details

Copy skill directory
  • Install or run with Copy skill directory

When to use supply-chain-security Skill

  • Use it for security review.

Built with

PowerShellCopy skill directory

Editorial notes

Source

  • Creator: microsoft
  • Repository: microsoft/hve-core
  • Skill file: .github/skills/security/supply-chain-security/SKILL.md

What it does

Software supply chain security reference for OpenSSF Scorecard, SLSA, Sigstore, SBOM, and posture/backlog taxonomies.

Skill instructions

Supply Chain Security This skill packages the durable software supply chain security (SSSC) reference material: open-standard catalogs, the combined capabilities inventory, and the classification taxonomies used to assess a repository's posture and turn gaps into prioritized work items. When to use Use this skill when you need to: Assess a repository against the 27 combined supply chain capabilities from hve-core and physical-ai-toolchain. Map posture against OpenSSF Scorecard, SLSA v1.0, OpenSSF Best Practices Badge, Sigstore (cosign), or NTIA SBOM minimum elements. Classify a gap by adoption category, effort size, or qualitative concern level. Derive work item priority and execution order from Scorecard risk levels. Skill layout Load the reference file for the topic you need. Each file holds the verbatim standard catalog or taxonomy. | Reference | Topic | |--------------------------------------------------------------------------------|------------------------------------------------

Explore related resources

Frequently asked questions

What is supply-chain-security?

supply-chain-security is a open-source AI agent skill with Copy skill directory. Software supply chain security reference for OpenSSF Scorecard, SLSA, Sigstore, SBOM, and posture/backlog taxonomies.

Who is supply-chain-security best for?

supply-chain-security is best for reusing agent instructions, scripts, and references, security review workflows.

How do I install supply-chain-security?

Install or run supply-chain-security using Copy skill directory. Check supply-chain-security for the latest setup command.

Is supply-chain-security actively maintained?

supply-chain-security may need a closer maintenance check before production use.

Share:

Stars
1,263
Forks
229
Last commit
9 days ago
Repository age
9 months
License
MIT

Auto-fetched from GitHub.

Ad
Favicon

 

  
 

Similar to supply-chain-security